Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m2w4-8ggf-rj47 | HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service |
Sat, 25 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* |
Sat, 18 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 17 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
Fri, 17 Apr 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16. | |
| Title | Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-04-17T17:57:55.431Z
Reserved: 2026-03-05T16:37:23.520Z
Link: CVE-2026-3605
Updated: 2026-04-17T13:20:25.836Z
Status : Analyzed
Published: 2026-04-17T04:16:03.263
Modified: 2026-04-25T18:08:13.057
Link: CVE-2026-3605
OpenCVE Enrichment
Updated: 2026-04-18T09:30:25Z
Github GHSA